REA: Let AI agents reverse engineer software without source code
The open-source project REA (Reverse Engineer Anything) connects reverse-engineering tools to AI coding agents such as Claude Code, Codex, and Cursor. If you spot a useful feature in someone else’s app, you can ask an agent to take the program apart, explain how the feature works with supporting evidence, and then build something similar in your own project. Reverse engineering means figuring out how a compiled program was written when you don’t have its source code.
REA is an MCP service. MCP is a standard interface that lets AI agents call external tools. Once connected, an agent can call REA’s analysis features directly in a conversation. Setup takes just one command, npx rea-agents setup. It registers REA with agents such as Claude Code, Codex, Cursor, Gemini CLI, and Grok Build, backing up your settings and asking for confirmation before changing them. You can also run commands directly in a terminal if you don’t use an agent.
REA can analyze many kinds of software. Native programs—software compiled directly into machine code—can be analyzed with disassemblers such as Hopper, Ghidra, or IDA, which translate machine code into assembly and C-like pseudocode. Electron apps—desktop software built with web technologies, such as Notion—can be examined by unpacking the ASAR archive in the installer and tracing modules and inter-process communication, without any additional tools. REA also supports .NET programs, Android APKs, firmware, websites, network capture files, Ethereum contract bytecode, and recording program behavior at runtime on Linux and macOS.
Analysis happens locally, and REA does not upload the target program. However, the results are sent to the AI model provider behind the agent; how that data is handled depends on each provider’s policies.
The project includes three case studies. First, the classic brick-breaker game DX-Ball: starting from a call that plays a sound effect, the analysis traces to a function that calculates the left and right audio channels based on the ball’s position. It reconstructs incomplete pseudocode as C code, and all 3,205 test results match the original; the 63 bytes of compiled output are also identical to the original. Second, the Notion desktop app: tracing the full path of copy-and-paste from the interface through the preload script and inter-process communication to the main process. Third, the game Touhou Fuumaroku (TH04) for Japan’s vintage PC-98 computer: recovering the angle-calculation algorithm for rings of bullet patterns from 16-bit instructions.
For security researchers and people recreating classic games or preserving software, work that once meant poring over disassembly tools line by line and tracing calls layer by layer can now be handed to an agent first, with a person checking the evidence it provides. Developers who want to explore how a competitor implemented a particular feature have another option, too.
The README says the project has already earned 50,000 stars on GitHub. The npm package was first released this July, and the latest version, 6.3.0, came out today.
A couple of things to keep in mind before using it. The project says it supports only lawful reverse-engineering research; users are responsible for authorization and compliance, and reverse engineering someone else’s software may violate its terms of service or copyright laws. The project also says it has never issued or endorsed any cryptocurrency; tokens using the REA name are unrelated to it.
https://github.com/morluto/rea
The open-source project REA (Reverse Engineer Anything) connects reverse-engineering tools to AI coding agents such as Claude Code, Codex, and Cursor. If you spot a useful feature in someone else’s app, you can ask an agent to take the program apart, explain how the feature works with supporting evidence, and then build something similar in your own project. Reverse engineering means figuring out how a compiled program was written when you don’t have its source code.
REA is an MCP service. MCP is a standard interface that lets AI agents call external tools. Once connected, an agent can call REA’s analysis features directly in a conversation. Setup takes just one command, npx rea-agents setup. It registers REA with agents such as Claude Code, Codex, Cursor, Gemini CLI, and Grok Build, backing up your settings and asking for confirmation before changing them. You can also run commands directly in a terminal if you don’t use an agent.
REA can analyze many kinds of software. Native programs—software compiled directly into machine code—can be analyzed with disassemblers such as Hopper, Ghidra, or IDA, which translate machine code into assembly and C-like pseudocode. Electron apps—desktop software built with web technologies, such as Notion—can be examined by unpacking the ASAR archive in the installer and tracing modules and inter-process communication, without any additional tools. REA also supports .NET programs, Android APKs, firmware, websites, network capture files, Ethereum contract bytecode, and recording program behavior at runtime on Linux and macOS.
Analysis happens locally, and REA does not upload the target program. However, the results are sent to the AI model provider behind the agent; how that data is handled depends on each provider’s policies.
The project includes three case studies. First, the classic brick-breaker game DX-Ball: starting from a call that plays a sound effect, the analysis traces to a function that calculates the left and right audio channels based on the ball’s position. It reconstructs incomplete pseudocode as C code, and all 3,205 test results match the original; the 63 bytes of compiled output are also identical to the original. Second, the Notion desktop app: tracing the full path of copy-and-paste from the interface through the preload script and inter-process communication to the main process. Third, the game Touhou Fuumaroku (TH04) for Japan’s vintage PC-98 computer: recovering the angle-calculation algorithm for rings of bullet patterns from 16-bit instructions.
For security researchers and people recreating classic games or preserving software, work that once meant poring over disassembly tools line by line and tracing calls layer by layer can now be handed to an agent first, with a person checking the evidence it provides. Developers who want to explore how a competitor implemented a particular feature have another option, too.
The README says the project has already earned 50,000 stars on GitHub. The npm package was first released this July, and the latest version, 6.3.0, came out today.
A couple of things to keep in mind before using it. The project says it supports only lawful reverse-engineering research; users are responsible for authorization and compliance, and reverse engineering someone else’s software may violate its terms of service or copyright laws. The project also says it has never issued or endorsed any cryptocurrency; tokens using the REA name are unrelated to it.
https://github.com/morluto/rea